Back to overview

CVE-2026-28353

CRITICAL
10.0
CVSS 4.0
Description
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users using the affected artifact are advised to immediately remove it and rotate environment secrets. The malicious artifact has been removed from the marketplace. No other affected artifacts have been identified.

Metadata

CVE ID
CVE-2026-28353
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-02-26 18:38 UTC
Published
2026-03-05 20:02 UTC
Last updated
2026-03-06 17:04 UTC
Primary CWE
CWE-506
CWE-506: Embedded Malicious Code
Vendor / Product
aquasecurity / trivy-vscode-extension
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
aquasecurity trivy-vscode-extension = 1.8.12
Weakness (CWE)
CWESourceDescription
CWE-506 cna CWE-506: Embedded Malicious Code
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
References (1)
Back to overview